EU Cyber Resilience Act Triggers First Reporting Duties on Sept 11, 2026
Cologne – – September 15, 2026 -- Manufacturers of connected devices, industrial controls, routers and software products face their first binding reporting deadline under the EU Cyber Resilience Act (CRA) on September 11, 2026, when mandatory notification of actively exploited vulnerabilities and severe security incidents begins via a centralized EU reporting platform.
Manufacturers must report exploited flaws within 24 hours
Under the CRA, manufacturers must submit an early warning within 24 hours of learning that a vulnerability in their own product is being actively exploited, followed by a supplementary report within 72 hours. A final report is due no later than 14 days after a remediation or risk-mitigation measure is implemented.
Severe security incidents affecting product security carry the same 24-hour and 72-hour notification windows, with a final report required within one month of the incident report.